<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to change sourcetype for HEC data input? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-change-sourcetype-for-HEC-data-input/m-p/627588#M107726</link>
    <description>&lt;P&gt;TYVM for the reply and info / so basically I'll be ingesting security and request events into the same index with the same sourcetype, but using the source name to distinguish between the two as I can name the HEC data input for WAF requests differently, which will then allow me to filter (and tag) security and requests.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 13:53:06 GMT</pubDate>
    <dc:creator>jwalzerpitt</dc:creator>
    <dc:date>2023-01-19T13:53:06Z</dc:date>
    <item>
      <title>How to change sourcetype for HEC data input?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-change-sourcetype-for-HEC-data-input/m-p/627578#M107724</link>
      <description>&lt;P&gt;In my Splunk Cloud instance, I am ingesting WAF security events from a SaaS service via HEC. The events are in JSON format so my HEC data input is configured as a sourcetype of&amp;nbsp;&lt;SPAN&gt;_json.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I now need to ingest the WAF request events from the Saas service, which are also in JSON format, so I'd like to send those to the same index, but with a different sourcetype to distinguish the two types of events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I modify the sourcetype for the WAF security events&amp;nbsp; from _json to waf_sec and then create a new HEC data input for the WAF request events with a sourcetype of waf_req, yet retaining the JSON format?&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 13:23:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-change-sourcetype-for-HEC-data-input/m-p/627578#M107724</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2023-01-19T13:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to change sourcetype for HEC data input?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-change-sourcetype-for-HEC-data-input/m-p/627585#M107725</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/103102"&gt;@jwalzerpitt&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since it may not be easy to default _json sourcetype, you can filter&amp;nbsp;&lt;SPAN&gt;waf_sec events using the source field. Filtering events by the source field is efficient like sourcetype.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 13:44:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-change-sourcetype-for-HEC-data-input/m-p/627585#M107725</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2023-01-19T13:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to change sourcetype for HEC data input?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-change-sourcetype-for-HEC-data-input/m-p/627588#M107726</link>
      <description>&lt;P&gt;TYVM for the reply and info / so basically I'll be ingesting security and request events into the same index with the same sourcetype, but using the source name to distinguish between the two as I can name the HEC data input for WAF requests differently, which will then allow me to filter (and tag) security and requests.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 13:53:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-change-sourcetype-for-HEC-data-input/m-p/627588#M107726</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2023-01-19T13:53:06Z</dc:date>
    </item>
  </channel>
</rss>

